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Abstract of JP2000347846 

PROBLEM TO BE SOLVED: To confirm that 
software is downloaded from a proper server and 
produced by a proper software producer by 
comparing a first checksum with a second 
checksum and checking the intrinsicalness of the 
software in a terminal. 

SOLUTION: A digital certificate for confirming the 
intrinsicalness of software to be transferred is 
added and the software is uploaded to a server 
(S300 and S302). By calculating and enciphering 
a checksum, an electronic sign is generated 
(S304 and S306). The required software is 
downloaded from the server to a terminal (S308). 
The checksum of the downloaded software and 
the added certificate is calculated and the 
intrinsicalness of the software is checked (S310). 
The enciphered electronic sign is deciphered 
while using a public key of the server (S312). The 
checksum, which is calculated by the server, 
obtained as a result of deciphering is compared 
with the checksum calculated by itself and the 
intrinsicalness is determined (S314). 
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^N'( 128) (100, 1 02)^fy7hn' 

xTSr^'^yn-H-ri.SPgs y7h'>x 
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■t-^N'(128) *>f>ffi* (100, 1 
y-xnyta-:? ( l 34 ) A>A>-9-->''C (i 28) S 

Tfriey 7 k x r S: r -/ ro- K-f & gi© t , 

f+mt-|.SPgt . aXX/^-J"^ (12 8) *^f>ffl* ( 1 

00, 10 2) iX'mMvyh^aiTir'^yx3-vt 

( 1 28) {:feV^TB!FfEy7h'>xTt*tt'ei50y7 

H ^^L/c y 7 h X r*»/ofriEffi*tcfc v ^-cn 2 tof-x 

•y^'-tA$-4fi!c-ri.Sligi:. feJ:t/mi<OBirE^x-y^' 
1^i*^1ifieSS20f-x •y^'-^-AtibR-ri.C: Oltr 
ti^iZ}3\^XmiiVyh^xT(DMJEmi-x -y ^^-f 

[Ii^fl2] irfiEy7h':7xr*<iiit$iii.t#t::. 

-ec7)*IEttA>'«t«* (10 0. 102) tcfct^Tf-x 

[ft^ja3] miZVyh^xTtiXx/m^cot:!^ 
^fwN' (12 8) ^7)^iHgA>rS:fflV^■CBi■^{t§^^l. 

^m^x-y^-fAm%tizti>zi-}X. -^WN' ( 1 
28) iza^^xm^^^ yim.tmm^ttiii 

[iS*Ji4 ] fiE«^*-roBt#^l:*^ -^--A' ( 1 2 
8 ) <^^^*^#'SrfflV^-CS* (10 0, 102) tCfcV> 

[iil^«5] ffi*(100. 102) Ji. ^AV^;<?- 
F**MS*«0;<f- HSgffiOgS (206) co^-tciifA^ 
il^ i— t>-loc077"y^r-vgy$:^f)^LitC:i:2: 

y-^mm-rico^Z'ii^t^tilmMvy b^xT^m^ 
* y mz^^X'-^ hi}^^i)^i^x 'UMb 
^ix^iSy 7 h-^xTtcov^TcoffllfiSr-i-t^P- 
Srif-yN' (128) tcHII.:: fc, ^^J:t/tfrle1^-''^'{i. 

Meffi*tCi0gi: Miay 7 h '^x r ^jMs i: . 
iiiiifW^Mi. i(nvyV'Oxr^i<r>x=ii^}n^zu 
m-h ^ t . mwit thmm i f.ztm<rym. 
[11^316 ] mi<r)m. ( 10 0. 1 02). it/' 

i^^g*<D»)f^$:M|gfcj;l/f$i|»L, y7 h';7xTfcJ;t/ 
-rs J: ^CfltlS^fLTV^S-t-M' (12 8), 

/ctiisiso y 7 h X r^tim h tz^^cr^^m 

(204) i'kts^'yXTM.ffy^-^b 
•^-J^zn L y 7 h X T 2: T -y 7-n- H-r S J: d Cfil 



B!i$n;tmigct/c{4is^<oy-;?.3yh'a-^ ( 1 3 
4) , B5ie•t-''^>'oy7h'>xrSrr'>yo-^'-f^ 

J: ( 1 0 0, 1 0 2 ) t , Sr^tf« 

frie-9--A'(4, friey 7 h x risfrffiffi^tcr'^ yn 
-Y^tihmi,z. myv^xTcmsmmi-thw, 
1 <of-x -y ijy 7 h X rW'fJirf d \,zm 

^^fih:ib. iiiiVfmivyV'^xTti^y'^yu-Y 
^tifztk. y'^yx3-Y^fitzvyv^xri}^^^2(r> 
^x ••/ J; 3 izwiiiMMm^^ixhZ 

<^^x"/9^J^bYcmth:Lb^zXr.xvyv-^x7(n 

m.'&i'f-x-y9-rhiir>\.zm^^ii^^b. mw.b 
[ mm. 7 ] mmMi. mivyv^x rtimm 

fihb%^zi<r>%W^-^n^z^x •y^'-tl. i otcfllBgS 

irnms^ mi-^-f<'\i.msivyv^x7iiiix/ 

mm<^fz>^^z^^a)^x ^v^^j^mnth c: b i<zx 

^ b iimLbthmm. e tie«ico vxta . 
[mm9 ] itne^*{4. mm-^^^'iimt^^^m 

?>Zbi:^WLb-thm^eiztim<Oi^:^TJ^. 
[000 1 ] 

oiftf^j-snfc ir/sijffli-ts'^ j^;^T/.^f-A't im 

X, ffi*A^'*Sic*7t:«4«^coy7h'!7xrSriB1it-S^c 
<i,y7h':rxr^:J^'> ya~ VthfiibffiUmizmt 
[0002] 

[ts!*oswi3 mm.mi^^'fM.t^^^-^mztj:^^ 

0) , ^)Vy-W^i^:^'f-Ub\-^r>tzmMMMi^X'fJ^ 
i^mth%m^-^VV-9m%th^bi:i^'mb^£ 

mmm^zii\.^Ximb^ti^. ^m^t. m\iZ. -t 

th^lbifX'th. 

\.0 003'[m:thi/XrAiii:Um.b LTti, ^ 
«fl;iS, V^i3»9>SWLL(wirelesslocal loop) S*s 
P O S tJo (tl.^AV «t tX;<7 - H t ®ff i: Oiao 

mzm^mmn. ±mifi^t^t^j:i'^r(r)vyh 




[00 04] Z:iX—mtLX. mUi^XTM.i:m^^X 

mmiii^j^mmm'^XTMz-:)\,>xtkiit&, zco=y 
XTUi. ^^i^mmx'mmtmiit&mmm 

mt ixm.mthmmi\'^*'^j:mx'hiimcotaA^ 
x'h'oomimw.imih, ^t^'ttc^4r<7)9v 

X -x h X?- F . U n- K nlflg^r^JAt - K , m^- 
i5j;tX;&-h'Sft^atcf£5tTM^O. loc^lill;;!/- 

viz'^\^xm^d:&mmmmizt*<-^t&x'hi>. ^ 

I.. 

[0005] 

^ ^: U l^tc^T K ■< r SrSJ^f I. - H TT* U 

if-mxh'<). ^<r>t^^mmtwj:\^^b^£h, ^co 
[0006] ^^^tcM«-ri, ztL(>0)mzmut 

<7) ;>!? - H ^^^^ lE-r y 7 h X r 5: t> >5: V ^ffi* t ;<? - 

x7^y^yu^}i'thZbifiX'^h, 

[00 07] L*»L^r*^'4>. iO:^afc{±X^*^'J>l.. 
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v^l,, -:5^0:5^'>yo-.K§iii,'<.#y7h'>xr*^'^ 

ix, ®iE^:y7h'^xr*Jf^tJ:oT^<^ixTV^|,^ 
^y7 h-^xTfi. SHL-Cv^irVMqiisit^Koyir K 

[0008] 

: ±^<^mm^fmx'^ ixdiz, imaxx/^coum^ 
(^m^'wy h^xTi:y^yr3-vi-^t.zih(oijmiz 

\ }i\^X. Vyy-^xTMmaXX/a-^-CDMJEm 

m^-tmmm^vyh^xnznm^m. v-x 

3yfa-:J'*>/i>-9-->'N'^t'y 7 h'^xTiSrT'yT'a- 
b't-SSI®. Vyh^xTi5Xl/Wm(^t:lif>cr>^xy 

^^j^m%-t^m. tixm-.><p(:>^^txyy 
m^xm^^tii. ^%m<7)ij&ii^(,iz. vyh^x 

Tt^mnzy'^yxii- ^'§i^l)fft■t->'^'t^5^'^•cy 7 
h '^x rHW t ^c7)y 7 b -^x TcO^EttSrSligt 1.^ 
x>yi?-tAH«nf sgpg. vyh^x7i3<y'yya- 
i K$n;tfii:J^n'yo- H$n;ty 7 b'^xr*>'i>TOc 

j3V^Tll2c7)f-x-y:7-tA$-±fi£tl.SP§, fcit/ISl 
OtlFief-x •y^'-tfA$r^<7)SS2c0^x-y^-»fAi:Jt«5!-r 
I. t J: "5 Jfg*icfc >, y 7 h x r<^EHt2rf-x 

[0009] *^Bfl{i$ f>t. ^S^^O«*t 4ii*(7)i)# 
^M^g*3J:t;f0JfflIL, y7h'>xrfc<J:t/'5-fiic#jD§ 
it^viSEHMcOJtiftiT)-?- X -y ^thm-r I. J: 3 {rffifig 
$^l.TV^|,-9— A\ #gc*yi{i:1ilSoy7h'>xrS:fB 

-A't^ tVyh^x7i:7'yra-V-thXd {c«Bg 

§ti.y::*fct/i«1^coy-X3ytfi-^Sr^;^»', « 

**^;^fW^>fey7 b'^xrirr'^VD-h'fl.J: 

mfS,$tifzmm=^XTMzm-t&, ^^mcomm^^x 

! rACl3l>-C(±. y7h^xT*»'Jg*{cy'> 
yn-V^iiimz. V7h^x7(7)MlEmm,ti> 

||lC0f-x-y^-9-A^y7h'>xT t#iD-r I. i 3 t^ffi 

tk. y^yn-Y^ixi;iVyh^x7i}^hm2cr>i-x'y 

; S^l£0f-x-y^t^AS-|g2c0^x-y^-9-AtJtffiEt.|.^ 
t i y 7 h 7x rcDEIttSr^x -y^-t^X^lz 

m^^tix\>^i. 

[0010] (a!ja:?i/-A(i, :^wM(^nt L^mm 
^imt^. ^mmmizx^b. vyh^xT 




[00 1 1 ] 

[wm'mmm wt. if%mz-^\,^x. 
mmmtm^Lx. mmmim^Ltcifit^imm 
\,zmmth, OTTii, -mtLxr ^ 'j-?)VGsm 
mmmi^xTMzmmfh:Lt^zs:->xm^^tit<k 

<r>mmi. ^%(^^(r)mwmm^xm,^fi. y 
yv^3^77r')^-'^3y^m\>^xmf^^'it3fihm 
m^tsm.i^x. h%mi^xTMz)^im-f^<m.^ 
mx'h it\^oz tuBmx'hh . 

[00 12]|11«. -fe/l-^-iliS^'y h^-^'I^IT-H 

u'X'fMi. 0 4-1 0 6 2::frL.T»i 

^(BTS) 10 8-1 10 Wg^§iXTV>&1SgCO^ 

fmkipp) ioo-~io2mth. mmtt:. 

ij^^jimx'hix. ^<mx^w^i)-'himrh t c7)f 

mmi 0 8-1 1 Ott. amwfcti. 3K^- 

&my^yi 1 2-1 14^:frLT. ^ilit(7)Ktte^^©J 

ffli-r.ss%M*j»sisi 16-11 8tz«ii§ix-cv^ 

I. mmm^S.! 1 6-118c0^r{ifcV^oi:. 

ix<^{±e3*7'fyi2o-i 22^:jvL-c, mmum 

■^)i^y-mil^XTA(7)^<r>m(0^^i,zimy^ y 1 2 
6^jlfCafS:gj||-rS»i6a<i3cSi^ (MSG) 12 

[0013] ^J:m^'>x^Mi$ h^z. 1 0 

0-1 0 2<?)i#^ilIfflife<J:t/l£ffl-rs'gai^;^r/s-9- 

--'N'(PMS) 1 2 8S-«ixl.. -^It Urai^ffl^ix 

12 8*5. ^;t<i\ -etiS<*:GSM-t;l/7- 
a-h;< 'y-fe- >-'-(: y ^' (SM. SC) 13 2{C, X. 

25^yi>y3i-xi30^-Stl.x^m^iiX\^h. -fe 
)Vy-m:.i/X'rMZ'Z>\yX<n±^<mmi1}^< LXG 

smi/XTMzmt^i:><r>X'hhti^. ^(^WyyxrJ^ 
{,^mmt^±M<^mm^h^Lfih(^x'hix. a* 

mimmthzt f.z^ *)^)Vv-mii^xTMz^-mf 
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[0014] if.%^mi^XTMi^ h<.Z. 

d^y-xrjyh-ji.-^'l 34S:fiil., y-;^nye 
a-:? 1 3 4{i, ffift^-y h V-^' 1 3 60IJ;t(f-^ 

-/ h t ti\mm'' vY^—^iif 1 2 8 

tcS^^itl., ■9-wN'fej:txy-x3yfa-^'iiJt 

£^i:§ni.«i^)iftitttfccti>'aw=5ry7h';7x 

[0015] m2\t. ^Wn<nyXTUZi.h^Ji:^m 

•fe;W7-4ili^b7yx-A' (MS) 20 0i6i.X^2m.^ 
ig?(two-wire connection) ilLT'CliJOh^yj^— >''^2 0 

0 \.zm h mmm 2 o 2 § mm:i-- 7 > ( c p 
u) 2 04Sr(i;c.i., *iiBso«5t5{±s A.tc, mm^- 
'/V20Af.zw^^ixtMmfk2oemti. rr 

1/ y h H it h ;<? - K ^^JAV S t 
\.X'^Xi\.hZtifX'%h, Ji*«±, ^WWiFMiT) 
I.Jti6<7)^-f-\";y:J^^S (KE 
Y B ) 2 10. ^^?:JL- .y h ( D I S P ) 20 SiJctlf 

>f-\'7^y2 1 2i,mxv^l). «*{ii;t. X]^-ti2 

1 6i5J:rX-7'f ^'0)1^^2 1 8S:litAyX7U-ffltg 

^^gg(c:tS#a2 14. fcj;t^'i:«=5rti1@§l^t^tf 

2ool*l^ciffla^T'^,J:v^L. ftsv^ti, fliis^wi-c 

^ 15] t ^- >-> /rt t coio^n * <o 

[00 16] h7>'v'W'Cx:i.y h2 0 0c7)^fig«i:, 'i^ 
«^^ffifttl.;i:tS)l., i--yh2 0 0(it/::. is 

mm&iixx/m)mmzmth-kxm^u-i^ h y 

m^J-- 'y h 2 0 4 C0«tg{i. i^^ig$r$i|ffl-ri. ^ t 
(C^^l.. $i]fflli-'y htMWC-^'f^DTn-fe-y-^-, 

-^'Jiji#$iJiiw^- -y u i*jtciaii§nT 

miiXx/=§M.^j:t'm^. ^^mx-mn^tLXi^im 
P^<7)hh'mm^^x. mm-yhmmi. m 
mz. Mrmmm-mmm^y h^^mtm^j: 

[0017] t^^mmcr)miitfz. ^^commmiz 




10 0 18] m.lZi.*)imt^ti^V 7 h^xTli. 

mj-~'y b 2 0 4<^^t y rttcieii^tis. ssv 7 

[00 1 9] <?:(C. 03tCS^t;t7n-f-v-hS'#i( 

(c-rs. y7h'>xT<os]EitS:«iE-?--?)7ti^>{ctt, y 

7 h':7xTA\ KiEtt^lgar^^Oy-X^^ii^^f-M'fc 

ht. ^wmmimzt5\^x\i. ^^wyv^^r 

X TS:1^->'N'{::St Lr -y rn- K-r ^^tt^coa y t 

(JaTy-xnyhfi-^tS^-r) SriSS'J-t.2.Ci: 
^■simzthm%<7)r ^ j/':J';HEB8Sc7)t|«?:g{tS. 

[00 2 0] ia3(50XT>y 7*30 OttSV^TJi. y7h 
•^xTfJf^ti. -9-WN'{:(K3M$ill>^&y7h'>xT 

h. X^'vr3Q2X'\i. y7h'!7xT«i, m{4'-<y 

y7h'>xr$fJf^#oy-;^3yfa-:?*>f>7 

^'^'Q-KfcMaL'Cy-xnytjL-rJ'cTJiE 
BM^f-x-y^tS. 

[ 0 0 2 1 ] y7 h'>xr*>m{;:5^'»o-K$tis 

t^. ^WyV^xTlfi. mz^';VU~9\Zilim 

y7b'^xrc7)ajmiry7h'>xr*»4>«if2t'#i. 

Zti/^imX'hh. Z(0Bm<Ot:iif). Vyh'^3:TI,Z 
^-Ji;^ T 7 7* 3 0 6 tCfc V y 7 h X 71C^«D $ ix 
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a. y7h'!7xrjDj: t^ESMt:-^!' ^-c 7 r 3 o 4 

X'^ X y ? A S:ltff L . 7 r 3 0 6 -C'if t L < {i 

tliZh^tl^j:\^Xol'mhZtlzX'0 . Vyh'^xT 
iz^(7)^x'y^^At:nmi>Zb^zX'oX±^^tl 

h. f-x7;?-^AS*<4, ^m^izb^xii'ji^mm 
i:mmth:ibizX'oxm.-thzb'¥X'^h. m^t 

^tifmmmi-iztx'hi. m^-t^f yi4. mm*^ 

r3 0 6T-9--VN'tCj3V>Ty7 h'^^xTtCfttP^tll.. 

mit^tirzm.iiz<r>t^ . mMzi5\^xmt'-^'i 
m^^i>ztizxmm^tim. ^mmmm^zni,^ 
•c«i, ^mizt^x'ji^<Dm^itim^mm-th:ib 

¥X'^^. 

[0022] Xf 77°3 0 BT'ti. •^-J<.i]^h 

v^-Ct[5l«(c, ^'>yo-K$ii7ty7h'>xrt>J:y 

bf^Zi.-yX. Xt77°3 1 OXVyV'OxTcnmLm: 
^x7^'-rS. 4B5(5{i<}i:l:, XT 77-3 1 2t^;--A'<0 

^mt^^'im^-t^ZUzX ^■^-f^zi5\^X7y 

mm^. ■9--A'KTi+jE$ti^^x7^'-tA*<#'c> 

ilh, XT7r3 14T\ S-^H-SLTtf-xy 

f-WN'tc-Cim$ix/::f-x7:7-*fA5rJ:tfi? 

S-T'ti i: ^rl. . -fx 7 ^'■t?--i>*«-gtL^« 

^. vyv^x.rim'iLX'hh (x^-yrsie) 

f-x7;!'^^A*5-aL5rV^^tc{i. y7h'>xT«oy 
-X«i*iEf^< (Xf77-3 18) . y7h'!7xTSr 

[00 23] iXt::. y7h'>xrc7)|5^cor'>yn-K 

ll4tjJ:tX05cO7o-f-A— 
tlX^^l. Xt77*4 OOtcfeV^T, f «4S*«0;<? 
-hW)^a2 0 6|*lt3;<?-h'^tfAL/>:, Xt77' 
4 0 2T14. *-h'<7)M^:I.SItg, 

v^T^x7^'tl.. «S:<7)StRK*5fi]fflT'# SJ©^. i 

-^y{i<>:fcXT7r4 0 6tca;^ic:c:-c. mtR^tifz 

^)n^z-^tfix\-^ht^^t^i^3.-y'?th. rr^)^- 

-fii*XT7r4 0 8-c'raji& 
[0024] -ecorr 'J ^- 3 u 



• 



- h'*^m(7)«IJfigSr-^t?^ t ^m-t LT. a-1f {iff 

[ 0 0 2 5 ] rr 'J 'r-'y 3 >-*J*»ai^xTA w-A' 
±fc*)i.*^. S*«4;^r-7r4 i4tfcv^T. rri; 

*{4<j:tc^T7r4 1 b\,zii\\x. rr^y-iyayifZ 
4 1 8m*$as. «*{ii-ift. i^-r<#rr 

10 0 2 6] ::cOt#«*(4, Xr-yr4 2 0{;fcV>-C 

rr 'J 3 y(r)i-zisb\,zmm^mt =5: 5 ^ ^ U 
ji*n-ri>CtA»'T#l. (03(^3 12). WyXT-M. 
W-A'{4xf •yr4 2 2T% 3S*tJ:-5TjlftI$ii;t 

-etT, ::tOT7°y>--i/3y{4. X-r-y7'4 24 

[ 0 0 2 7 ] t ^ 1 rxDmcymmBWizii^yzii. mk 

3 yolf AS-^JW-tirr. tzfzmzrr^) ^--^ 3 y SrS 
*fc^j*t. ^<7)«5i5*<»:{i'?-oTru^-i^3y$-?- 

iDX-T, ^^•^yn-Hnisg^y7h'^xri4, :?-^At 
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L TITLE OF THE INVENTION 

METHOD FOR DOWNLOADING SOFTWARE FROM SERVER TO TRRMINAL AND 

TELEPHONE SYSTEM 

DETAILED DESCRIPTION OF THE INVENTION 

The invention relates to a method for downloading software from a 
server -1o a terminal in a telephone system comprising a plural number ot 
terminals and a management system sen/er that monitors and controb the 
operation of the torminats, a temninal of the system comprising means for 
storing one or more software. 

As radio telephone systems become increasingly common and their 
coverage areas grow - the systems often replacing those implemented by 
fixed line telephone connections - it has become necessary to develop 
telephone networks supporting radio telephone systems such as cellular radio 
systems. Such telephones are needed, for example, in areas where fixed line 
telephone connections do not exist, or in applications In which tha terminal Is 
in a place, for example in a moving vehicle, where connection to a fixed 
network is not easily avaifabfe. The present invention can be applied 
particularly to systems implemented by means of cellular radio systems. 

The systems and terminals involved include pay phones, so-called 
WLL (wireless local loop) terminals, payment terminals at points of sale and 
smart card terminals supporting transfer of money between a card and a bank. 

The functions in current torminals are to a large extent implemented 
by means of various types of software. The terminal comprises a processor 
and memory into whigh the necessary software is stored. When the user 
selects a function, the software is read from the memory and carried out. In 
the designing of terminals, a compromise between the number of functions 
and the available memory capacity has been necessary. Due to reasons of 
cost, the size of the memory in the terminals cannot be infinitely increased, 
therefore the memory limits the number of the functions. 

Let us study, by way of example, a pay phone system implemented 
by means of a radio system. The system cornprises a plural number of pay 
phones, Rach communicating with base stations over ^ radio path. For the 
radio path and the base station, the terminals functioning as pay phones do 
not deviate in any way from conventional subscriber terminals. For collGction 
of payments, the pay phonos comprise a collection device that can typically be 
a payment card reading device. Numerous different payment cards are 
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available, such as different types of credit cards, reloadable payment cards, 
bank cards, etc. In addition, the card types vary grjcording to the card 
manufacturer and the company offering the card, and different facilities can be 
selected for one and the sama card. Each card type requires the terminal to be 
provided with software supporting the card, \.o. a card ai>plication. The card 
application comprises the routines required for the terminal's user interface» for 
uontrolting the card and for performing a transaction, such as a payment. 

To have card applications supporting all card types stored into tlie 
memory of a terminal reading a card would fequire such a large memory that 
the terminal would be expensive. Furthermore, the adding of new card 
applications to the terminal would require tho software of the entire equipinent 
to be changed at hardware maintenance. 

Problems similar to those relating to pay phones also affect other 
wireless devices in which payment cards are read, such as reloading devices 
allowing electronic money to be loaded from a bank account to a payment 
card. 

To solve the above problem, it is advantageous if software can be 
downloaded through the networl^ when necessary, thereby allowing the 
terminal's memory to be optimally utilized. When a card is inserted into a 
terminal which does not have software correspondlny to the card, tho tBiminyl 
can download the needed software to its memory through the network from a 
predetermined server. 

This method has, however, its shortcomings. The use of software 
downloaded from a network involves risks that must be taken into account, ft is 
important that the software to be downloaded i?> flawless and doss not contain 
software vimses, for example, or otiier harmful elements. It is also important to 
be able to verify that the software Is downloaded from the correct servor and 
that It is manufactured by the correct software manufacturer. A defective 
software can cause malfunction In the terminal, such as unintended calls and 
transactions to wrong addresses. 

An object of the invention is therefore to provide a method and an 
apparatus Implementing the method so as to allow the above problems to be 

solved. This is achieved with a method for downloading software from a server 
to a temiinal, the method comprising the steps ot attaching to the software a 
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certificate confirming the authenticity of the software rronufacturer and the 
ioadar: downloading the software from a source computer to the server; 
calculating a check sun} for the softwara and the certificate; and downloading 
the software from the server to the terminal. The method of the invention 
further comprises the steps of adding the check sum confirming the 
authenticity of the software to the software at the server before the software is 
downloaded to terminals; generating a second check sum at the terminal from 
the downloaded software, after the software has been downloaded: and 
checking the authenticity of the software at the terminal by comparing the first 
check sum with the second. 

The Invention further relates to a toiephone system comprising a 
plural number of tarminals and a server monitoring and controlling the 
operation of the terminals, the server being arranged to calculate a check sum 
for the software and the certificate attached to the software; a terminal of the 
telephone system comprising means for storing one or more software, and the 
system comprising one or more source computers arranged to upload 
software to the server, the temiinals being arranged to download the software 
from the server. In the telephone system of the invention the server is 
arranged to attach to the software a first check sum confirming the authenticity 
of the software before the software is downloaded to the tenninals, and a 
terminal is arranged to generate a second check sum from the downloaded 
software, after the software has been loaded, and that the terminal is arranged 
to chock the authenticity of the software by comparing tha first dieck sum with 
the second. 

The dep3ndent claims relate to preferred embodiments of the 

invention. 

The method and system of the invention provide several 
advantages. With the solution of the invention it Is easy to ensure that the 
software is safe and that it is uploaded to the server from a safe sourco 
computer. The invention employs digital signature to ensure the authenticity of 
the software. Corresponding methods have earlier been applied only In 
connection with electronic mail transmissions. 
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3. BRIEF DESCKIPTIDN OF THE DRAWINGS 

In ths following the invention will be descrlbeid In greater detail In 
connection with preferred embodiments and with reference to the 
accompanying drawings, in which 

Figure 1 i3 a diagram Illustrating a structure of a telephone system 
of the invention: 

Figure 2 Is a block diagram illustrating a structure of a terminal of a 
system according to the invention; 

Figure 3 is a flow chart illustrating a method of the invention; and 
Figure 4 is a flow chart illustrating the downloading of software. 

In the following the invention will be described, by way of example, 
with reference to a pay phone system Implemented by applying a digital GSIVI 
mobile phone system, the Invention not beino, however, limited to the 
example. It is apparent that the solution of the invention can be modified to 
apply to telephone systems implemented by means of any other technology 
and comprising terminals which Include functions operated by means of 
software applications. 

Figure 1 illustrates a structure of a pay phons system injplementad 
in a cellular radio network. The system comprises a plural number of pay 
phones 100-102, each connected via a radio path 104-106 to base stations 
108-110. For the radio path or lite base station, terminals operating as pay 
phones do not differ in any way from conventional subscriber torminals. The 
base stations 108-110 are typically connected to base station controllers 116- 
118. each controller controlling a plural number of base stations, via 
transmission lines 112-114 which can be Implemented by means of optical 
cables, copper cables or link connections. The base station controllers 116- 
118. in turn, are connected via transmission linos 120-122 to a mobile services 
switching centre 124 which controls the operation of the base station 
controllers and transmits calls from the terminals to a fixed network or to other 
parts of the cellular radio system via transmission lines 126. 

The pay phone system further comprises a management system 
server 128 which controls and monitors the operation of the pay phones 100- 
102. In the GSM fiystom used as an example, a control equipment server 128 
of the pay phone system is connected via an X.25 interface 130, for example, 
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to a short message centre 132 which is, in turn, connected to GSM cellular 
networks and their mobile switching centres. The above description of the 
cellular radio system thus relates to the GSM system, but it is obvious that 
although the details of other systems vary from the above descr^tion. there 
are no essential structural differences. It should bo noted that also in the GSM 
system the pay phone system can be implomented without the short message 
centre, by connecting the control equipment server 128 of the pay phone 
system to the cellular radio system by omploying other prior ait methods, such 
as a modem. 

Trie system of the invention further comprises a source computer 
134, such as a computer of the manufacturer of the software used in the 
terminals. The source computer 134 \^ connected to the server 128 via a 
telecommunications network 136, such as the Internet or a private network. 
Both the servei and the source computer caii be implemented as computer 
hardware having the required telecommunicalions characteristics and the 
appiDpriate software. 

Figure 2 iffustrates an example of a preferred embodiment of a pay 
phone according to the system of the invention. The pay phone of the 
Invention comprisos a cellular radio transceiver 200 and a control unit 204 
which has a direct connection 202 to the transceiver 200 without a two-wire 
connection. The terminal of the invention further comprises a collection means 
200 connected tu the control unit 204. Depending on the apc)llcatlon, the 
collection means can accept phone cards, credit cards or smart cards as 
means of payment. The terminal typically also comprises a dialling means 210 
for dialling the desired telephone number, display unit 208 and an earpiece 
212. The terminal can also comprise means 214 allowing a hands free facility, 
the means comprising a speaker 216 and a microphone 218, and the 
necessary amplifioTs. If desired, some or all of the above components can be 
directly integrated into the transceiver 200, or they can be implemented as 
separate means, although structurally possibly within the same casing. 

The function of the traneceiver unit 200 is to provide, when 
necosoary. □ radio connection to a base station to allow a call to be 
transmitted. The unit 200 also takes care of all operations (usually canied out 
by a mobile phone) concerning the maintenancti of the radio path and the calf. 

The function of the control unit 204 is to control the pay phone. The 
control unit typically comprises a micro processor, fixed and reprogrammable 
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msmory circuits, muKiplewnfl means and switches. The control unit controls 
the operations of other units includsd in tha equipment, registers placed calls 
and takGs care of debiting. Tho oparatlonal parameters of the pay phone are 
usually stored in the control unit's memory. Such telephone-specific 
parameters include telephone number, tariff data relating to the calls to bo 
placed, language options on the telephone's display and volume of voice, 
Eifcept for tha Inventive features described In the present application, the 
operation of the control unit does not basically differ from the operation of the 
control units of prior art pay phones. 

The details of ihe terminal structure can also vary from the above 
description depending on the purpose of use of the terminal. For example, if 
the terminal is a payment terminal used at a point of sale, the device does not 
necessarily include audio parts such as a microphone or speaker. At its 
simplest, the terminal comprises a cellular radio transceiver, a control unit and 
collection moans which can ba structurally integrated with each other or, 
alternatively, they may be components detachable from one another and 
temporarily connected together for the duration of a call payment or a 
purchase transaction, for example. 

The software needed by the terminal are stored Into the memory of 
a control unit 204, The software concerned include software, or card 
applications, needed by various payment card alternatives. A card application 
comprises routines needed for the terminars user fnieiface, for controlling a 
card and for canying out a card transaction, such as a payment. 

Let us then study the method of the invention with reference to a 
flow diagram shown in Figure 3. As stated above, the system of trie Invention 
allows software to be downloaded to terminals, when necessary, from the 
system server. To ensure the authenticity of the software it is imjiortant that 
software can only be uploaded to the sen/er from a source the authenticity of 
which has been confimied. In the solution of the invention, each software 
supplier is therefore provided with a specific digital certificate that allows the 
software supplier, or the supplier's computer (hereinafter refened to as the 
source computer) from which the software Is uploaded to the sender, to be 
Identified. The certificato is granted by a third party, such as the terminal 
manufacturer. 

In step 300 of Figure 3, the software producer attaches a digital 
certificate confirming the authenticity of the software to the software to be 
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trandferred to a server In step 302 the software is uploaded from the software 
producer's source computer via, for example, the Internet or anotlier link to ihe 
network server which in this example is the server of the pay phone system. In 
a preferred embodiment of trie invention, the server checks the source 
computer's certificate in connection with tha downloading. 

When software is downloaded to terminals, it Is also ossential that 
the software is downloaded from an official server agreed on in advance and 
not from a disturber that has connected to the network. It is thersfore 
necessary that the origin of the software can be vohfied from the software. For 
this purpose the software Is provided with an alectronlc signature at the servor, 
the signature being attached to the software in stap 306. In ths prefen'ed 
embodiment of the Invention, the electronic signature is generated by 
calculating a check sum in step 304 for the software and the oertltlcate and by 
attaching the check sum to the software in step 306, preferably by using 
encryption, thereby preventing any extemal party from corrupting the sum. The 
check sum Itself can be calculated by applying methods known to those skiilod 
in the art. One way of implementing the encryption is to use a public key and 
secret key encryption method. The electronic signature is attached to the 
software at the server in step 306 by using the 5Gn/Hr*s secret key which 
outsiders do not know. The encrypted information can then be decrypted by 
using a public key at the terminal. In the solution of the invention, encryption 
methods known to those skilled in the art can be used. 

In step 308 the terminal downloads the software needed from the 
server. After th(3 terminal has downloaded the software, it checks the 
authenticity of the software in step 310 by calculating, similarly as at the 
server, the check sum of the downloaded softwaro and the certificate attached 
to the software. The terminal then decrypts the encrypted electronic signature 
attached to the software at the server in step 312 by using the server's public 
key. As a result of the decryption, the check yum calculated at the sen/er Is 
obtalnsd. The tenminal compares the check sum it has calculated with that 
calculated at the server in step 314, the result of the comparison allowing the 
terminal to decide the authenticity. If tho chGck sums match, the software is 
authentic (steij 310). but If the check sums do not matci\ the source of the 
software is not authentic (stop 313) and the software caniiot be taken into use. 

Let us then study an example of a situation where the above 
doscribed downloading of the sofh/vare cannot be carried out; this is illustrated 
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In a flow diagram of Figure 4, In step 400 the user has inserted a card into a 
card reader 206 of a terminal, in step 402 the terminal checlcs the different 
functions of the card, for example, any credit card alternatives Included. If 
several options are available, the user get^ to select the function to be used. 
The routine then proceeds to step 406 to check whether an application 
required by the selected function is included in trie terminal's memory. The 
application koeps record of the applications available in Its memory at a 
particular moment. If the application is in the memory, It can be started in step 
408. 

If the application is not in the terminars memory, the routine 
proceeds to step 410 to check whether the application Is in the management 
system's server. Information about the applications that can be downloaded 
from the server can be stored either in the terminal, or the terminal can 
request the Information from the sender. If the application cannot be found from 
the management system, the function Is rejected In step 412 and the usor is 
asked to give a new one, provided that the card contains several functions. 

If the application is on the management system's server, the 
terminal asks in step 414 the amount of memory required by the application. 
The terminal then checks in step 410 whether the amount of memory requirad 
by the application available. If thero is not enough memoiy available, an 
application to be removed from the memory is selected and removed in step 
418 so as to release memory for the new application. The temilnal can let the 
user solect the application to be removed or. alternatively, the terminal can 
make the decision on the basis of a predetermined critsiion. One criterion is to 
keep recently used applications and to remove an application that has been 
unused for the longest. 

The temiinal then Informs in ^tep 420 the sender of a free memory 
area where thG application should be placed. For example, the terminal can 
Inform a memory area 312, shown in Figure 3, to be available for the 
application. The managemer)t system's server downloads in step 422 the 
application to the memory area informed by the terminal. The application is 
then ready to be taken into use In step 424. 

In another alternative embodiment the management system's 
server doos not control the placing of the application into the terminars 
memory, but only transmits the application to the terminal which then places 
tho application into its memory. 
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In addition to payment card applications, a downloadable software 
can comprise facilitiea transferred in an electronic form, such as timetable 
intomriation or tickets. 

Method steps associated with the temilnal of the Invention can be 
advantageously lmplem<»nted by software at the temiinal's control unit 204. 
The connection to the management system's server required by the method 
can be advantayeously provided by means of a data call connection. A data 
call is a call type that is available In digital radio networks; it corresponds to a 
modom connection in analog systems. 

At the management systenVs server and in the software 
manufacturer's source computer the functions of the invention can be 
advantageously implemented by means of softwara. 

Although the invention is described above with reference to an 
example shown in the attached drawings, it is apparent that the invention is 
not restricted to It. but cart vary in many ways within the invontive idea 
disclosed in the attached claims. 
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4. CLAIMS 

1. A methQd for downloading software from a server (128) io a 
terminal (100. 102). the method comprising thei steps of 

attaching to the software a certificate confirming the authenticity of 
ihe softwgre manufacturer and the loader. 

uploading the software from a source computer (134) to the server 

(128): 

calculating a check sum for the software and the certificate; and 
downloading the software from the sen/er (128) to the terminal 
(100, 102). 

characterized in that the method further comprises the 

steps of 

attaching the chock sum confirming the authenticity of the software 
to thG sofhware at the server (128) before thn software is downloaded to 
terminals; 

generating a second check sum at the terminal from the 
downloaded software, after the software has been downloaded; and 

checking the authenticity of the software at the terminal by 
comparing the first check sum with the second. 

2. A method according to claim 1, characterized In that t)ie 
authenticity of the software is always checked at the terminal (100, 102) when 
the software is carried out. 

3. A method according to claim l.oharacieri^ed in that the 
method comprises the generating of an electronic signature at the server (128) 
by calculating for the software and ihe certificate a common check sum which 
is encryptad by means of a secret kay of the server. 

4. A method according to claim 3, characterized in that the 
encryption of the secret key is decrypted at the tsrminal (100, 102) by means 
of a public key of the server (128). 

5. A method according to claim 1, characterized in that the 
terminal (100, 102) detects that a payment card is inserted Into the terminal's 
card reader (206) and the user has >;elected an application, and that the 
terminal 

checks whether the !»oftwaro neoded fur implementing the 
application can be found in the torminars memory, and 
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sends the server (128) a loading request conr^prlsing infomnation 
about the software needed, and that the server 

sends the terminal the software needed, and that the tern iinal 
stared the software into, its memory. 

6. A telephons system comprising 

a plural number of tenninals (100, 102) and 

a server (128) monitoring and controlling the oparation of the 
terminals, the sen/er (128) being arranged to c?jlculate a check sum for 
software and for a certificate attached to the software; 

a terminal of the telephone system comprising means (204) for 
storing one or more software, and the system comprising 

one or mors source computers (134) arranged to upload software to 
the server, the terminals (100. 102) being arranged to download software from 
the seiver, 

characterizod in that 

the sGH/er is arranged to attach 1o the softwaro a first check sum 
confirming the authenticity of the software before the software is downloaded 
to the terminals, and that 

a terminal is anranged to generate a second check sum from the 
downloaded software, after thG software has been loaded, and that the 
terminal is arranged to ch3ck the authenticity of the software by comparing the 
first check sum with the second. 

7. A system according to claim 6. characterised in that the 
terminal is arranged to always check the authenticity of software when the 
software is carried out. 

8. A system according to claim 6, characterized in that the 
server is arranged to generate an electronic signature by calculating for the 
sofhware and the certificate a common check sum and to encrypt the 
calculated check sum by moans of a sacr^t key of the sender. 

9. A system according to claim 6, c h a r a c 2 e r i % e d in that the 
terminal is arranged to decrypt the encryption of the electronic signature by 
means of a public key of the sender. 
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1. ABSTRACT 

The invontlon ralatds to a telephone systsm and a mtHhod for downloading 
software from a server (128) to a terminal (100, 102), the method comprising 
the steps of attaching to the software a certificate confirming the authenticity of 
the software and the loader; downloading the software from a source 
computer (134) to the server (128); downloading the software from the server 
(128) to the terminal (100, 102). In the inethod of the invention a first electronic 
signature confirming the authenticity of the software is attached to tha softwaro 
at the servor (128), After the software is downloaded, a second electronic 
signature is generated at the terminal from the loaded software and the 
authenticity of the software is checked by comparing the first electronic 
signature with the second. 

2. REPRESENTATIVE DRAWING 

Figure 1 




